Insecure Direct Object Reference Vulnerability in MphRx's Minerva Product
CVE-2026-5780

8.5HIGH

Key Information:

Vendor

Mphrx

Status
Vendor
CVE Published:
28 April 2026

What is CVE-2026-5780?

The vulnerability in MphRx's Minerva product allows authenticated users to exploit an insecure direct object reference (IDOR) in the '/minerva/moUser/show/' endpoint. By modifying the ID parameter, users can gain unauthorized access to the sensitive data of other registered users, potentially compromising user privacy and data integrity. This issue highlights the need for improved access control measures to safeguard personal information.

Affected Version(s)

Minerva 3.6.0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alejandro Rivera León
.